CVE-2025-64056 Details
Description
File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.
A file upload vulnerability exists in the Fanvil X210 V2 IP phone running firmware 2.12.20. This vulnerability allows unauthenticated attackers on the local network to upload arbitrary files to the device's filesystem. The issue arises because the web application used for device configuration does not properly validate or sanitize file paths in upload requests. Exploitation of this vulnerability could lead to unauthorized modification of the device's behavior, as the web service operates with root privileges.
Users are advised to update to firmware version 2.12.22.2, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64056.md | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| fanvil x210 firmware | 2.12.20 |
CPE
Remediation
| |
| fanvil x210 | 2.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 9, 2026 | Modified Analysis | [email protected] |
| Dec 11, 2025 | Initial Analysis | [email protected] |
| Dec 8, 2025 | CVE Modified | CISA-ADP |
| Dec 5, 2025 | New CVE Received | [email protected] |